LuftID Log In

Privacy Policy

Last Updated: December 3, 2025

IMPORTANT: Please read this Privacy Policy carefully to understand how we collect, use, disclose, and safeguard your information when you use our Service. By using the Service, you consent to the data practices described in this policy.

1. Introduction

This Privacy Policy ("Policy") describes how LuftID ("Company", "we", "us", "our") collects, uses, discloses, and protects your information when you use our website, application, API, and related services (collectively, the "Service").

We are committed to protecting your privacy and handling your data in an open and transparent manner. This Policy explains what information we collect, how we use it, and your rights regarding your information.

By accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with our policies and practices, you must not use the Service.

2. Information We Collect

2.1 Information You Provide

We collect information that you voluntarily provide to us when you:

  • Create an Account: When you register for an account, we collect your username, email address, and password (which is hashed and not stored in plain text).
  • Upload Images: When you upload images to the Service, we collect and store those images along with any metadata associated with them.
  • Use the Service: We collect information about your use of the Service, including search queries, selected sources, and preferences.
  • Contact Us: If you contact us for support or other inquiries, we collect your name, email address, and the content of your communications.
  • Payment Information: If you purchase a subscription, our payment processors collect billing information, including credit card details, billing address, and payment history. We do not store full credit card numbers on our servers.

2.2 Automatically Collected Information

When you use the Service, we automatically collect certain information about your device and usage patterns:

  • Device Information: IP address, browser type and version, operating system, device type, and device identifiers.
  • Usage Data: Pages visited, features used, time spent on pages, clickstream data, and navigation patterns.
  • Log Data: Server logs, including access times, error logs, and system performance data.
  • Cookies and Tracking Technologies: We use cookies, web beacons, and similar tracking technologies to collect information about your interactions with the Service. See Section 9 for more details.

2.3 Derived and Processed Data

We process uploaded images to create facial recognition data:

  • Facial Templates/Descriptors: We generate numeric vectors (facial templates) from uploaded images using facial recognition algorithms. These templates are used for matching purposes and do not contain the original image data.
  • Search History: We store records of your searches, including timestamps, selected sources, and search results (candidates with similarity scores).
  • Analytics Data: We may aggregate and anonymize data for analytics, research, and service improvement purposes.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Provide and Maintain the Service: To process your image uploads, perform facial recognition matching, and deliver search results.
  • Account Management: To create and manage your account, authenticate your identity, and provide customer support.
  • Service Improvement: To analyze usage patterns, improve our algorithms, enhance service performance, and develop new features.
  • Communication: To send you service-related notifications, updates, security alerts, and administrative messages.
  • Billing and Payments: To process payments, manage subscriptions, and handle billing inquiries.
  • Security and Fraud Prevention: To detect, prevent, and address security issues, fraud, and unauthorized access.
  • Legal Compliance: To comply with applicable laws, regulations, legal processes, and government requests.
  • Research and Analytics: To conduct research, perform analytics, and generate statistical insights (using anonymized data where possible).
  • Enforcement: To enforce our Terms of Service and other policies, and to protect our rights and the rights of others.

4. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA) or United Kingdom, we process your personal data based on the following legal grounds:

  • Consent: When you voluntarily provide information, such as when you create an account or upload images.
  • Contract Performance: To fulfill our contractual obligations to provide the Service to you.
  • Legitimate Interests: To improve our Service, ensure security, prevent fraud, and conduct business operations, where such interests are not overridden by your rights.
  • Legal Obligations: To comply with applicable laws and regulations.

You have the right to withdraw consent at any time, though this may affect your ability to use certain features of the Service.

5. How We Share Your Information

We do not sell your personal information. We may share your information in the following circumstances:

5.1 Service Providers

We may share information with third-party service providers who perform services on our behalf, including:

  • Cloud hosting and storage providers
  • Payment processors
  • Analytics and monitoring services
  • Email service providers
  • Customer support platforms

These service providers are contractually obligated to protect your information and use it only for the purposes we specify.

5.2 Legal Requirements

We may disclose your information if required to do so by law or in response to valid requests by public authorities, including:

  • Court orders, subpoenas, or other legal processes
  • Government investigations or regulatory inquiries
  • To protect our rights, property, or safety, or that of our users or others
  • To enforce our Terms of Service or other agreements

5.3 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of assets, your information may be transferred to the acquiring entity, subject to the same privacy protections.

5.4 With Your Consent

We may share your information with third parties when you explicitly consent to such sharing.

5.5 Aggregated and Anonymized Data

We may share aggregated, anonymized, or de-identified information that cannot reasonably be used to identify you for research, analytics, or other purposes.

6. Data Retention

We retain your information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

  • Account Information: We retain account information for as long as your account is active and for a reasonable period thereafter to comply with legal obligations and resolve disputes.
  • Uploaded Images: We retain uploaded images and associated facial templates for the duration of your account and for a reasonable period after account deletion, subject to legal requirements.
  • Search History: Search history is retained according to your subscription plan (1 day for Trial, 7 days for Standard, 30 days for Pro) and may be retained longer for legal or security purposes.
  • Log Data: Server logs and technical data are typically retained for up to 12 months, unless required longer for security or legal purposes.
  • Legal Requirements: We may retain certain information longer if required by law, regulation, or legal process, or to protect our legal rights.

When you delete your account, we will delete or anonymize your personal information from active systems within a reasonable timeframe, though some information may remain in backups for a limited period.

7. Data Security

We implement reasonable technical and organizational security measures designed to protect your information from unauthorized access, use, disclosure, alteration, or destruction. These measures include:

  • Encryption of data in transit using SSL/TLS
  • Encryption of sensitive data at rest
  • Secure password hashing and storage
  • Access controls and authentication mechanisms
  • Regular security assessments and updates
  • Employee training on data security

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security. You use the Service at your own risk regarding the security of your data.

You are responsible for maintaining the confidentiality of your account credentials and for all activities that occur under your account.

8. Your Rights and Choices

Depending on your location, you may have certain rights regarding your personal information:

8.1 Access and Portability

You have the right to request access to your personal information and to receive a copy of your data in a structured, commonly used format.

8.2 Correction

You have the right to request correction of inaccurate or incomplete personal information.

8.3 Deletion

You have the right to request deletion of your personal information, subject to certain exceptions (e.g., legal obligations, legitimate business interests).

8.4 Restriction of Processing

You have the right to request restriction of processing of your personal information in certain circumstances.

8.5 Objection to Processing

You have the right to object to processing of your personal information based on legitimate interests or for direct marketing purposes.

8.6 Withdrawal of Consent

Where processing is based on consent, you have the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before withdrawal.

8.7 Opt-Out of Marketing

You can opt-out of receiving marketing communications from us by following the unsubscribe instructions in our emails or by contacting us.

8.8 Account Deletion

You can delete your account at any time through your account settings or by contacting us. Account deletion will result in the removal of your personal information, subject to our retention policies.

To exercise these rights, please contact us at privacy@luftid.com. We will respond to your request within a reasonable timeframe and in accordance with applicable law. We may need to verify your identity before processing your request.

9. Cookies and Tracking Technologies

We use cookies, web beacons, and similar tracking technologies to collect and store information about your use of the Service.

9.1 Types of Cookies

  • Essential Cookies: Required for the Service to function properly, including authentication and security features.
  • Functional Cookies: Remember your preferences and settings to enhance your experience.
  • Analytics Cookies: Help us understand how users interact with the Service to improve performance.
  • Session Cookies: Temporary cookies that are deleted when you close your browser.
  • Persistent Cookies: Remain on your device for a set period or until you delete them.

9.2 Managing Cookies

You can control cookies through your browser settings. Most browsers allow you to refuse or delete cookies. However, disabling cookies may affect the functionality of the Service.

We do not respond to "Do Not Track" signals from browsers at this time.

10. Third-Party Links and Services

The Service may contain links to third-party websites, services, or resources that are not owned or controlled by us. We are not responsible for the privacy practices or content of these third-party sites.

When you click on links to external sites, you are subject to their privacy policies and terms of service. We encourage you to review the privacy policies of any third-party sites you visit.

Search results may include links to external websites where matched images were found. We do not control the content or privacy practices of these external sites.

11. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your country.

When we transfer your information internationally, we take steps to ensure appropriate safeguards are in place, including:

  • Standard contractual clauses approved by relevant data protection authorities
  • Compliance with applicable data protection laws
  • Implementation of appropriate security measures

By using the Service, you consent to the transfer of your information to countries outside your country of residence.

12. Children's Privacy

The Service is not intended for individuals under the age of 13 (or the age of majority in your jurisdiction, if higher). We do not knowingly collect personal information from children under 13.

If you are a parent or guardian and believe that your child has provided us with personal information, please contact us immediately. If we become aware that we have collected personal information from a child under 13, we will take steps to delete such information promptly.

13. Opt-Out and Takedown Requests

If you believe that an image or link in our search results is incorrect, violates your rights, or should be removed, you may submit an opt-out or takedown request.

We will review and process valid requests in accordance with applicable law, including:

  • DMCA takedown requests for copyright infringement
  • GDPR requests for removal of personal data
  • Requests to remove incorrect or misleading information

To submit a request, please contact us at privacy@luftid.com with the following information:

  • Your contact information
  • Description of the content you want removed
  • URL or identifier of the content
  • Reason for the request
  • Any supporting documentation

We will respond to valid requests within a reasonable timeframe and in accordance with applicable law.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

We will notify you of material changes by:

  • Posting the updated Privacy Policy on this page with a new "Last Updated" date
  • Sending an email notification to the address associated with your account (for material changes)
  • Displaying a prominent notice on the Service

Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated Privacy Policy. If you do not agree to the changes, you must stop using the Service and may delete your account.

We encourage you to review this Privacy Policy periodically to stay informed about how we collect, use, and protect your information.

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at privacy@luftid.com.

For data protection inquiries, please include "Privacy Policy Inquiry" in the subject line of your email.

We will respond to your inquiry within a reasonable timeframe and in accordance with applicable law.

Your Consent

By using the Service, you consent to the collection, use, and disclosure of your information as described in this Privacy Policy.

If you do not agree with this Privacy Policy, you must not use the Service.